RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix?
| From: | Gustafson, Mårten | Date: | Tue, 05 Sep 2000 13:27:04 +0000 |
| Subject: | RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix? | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32146@lists.php.net to get a copy of this message | ||
I don´t think anything has to be changed.
It´s not a hard thing to do $form = &$HTTP_POST_VARS at the top of each
script that should recive post data. Or have a general include file that
takes care of it.
Regards
Mårten
> -----Original Message-----
> From: Jon Ribbens [mailto:jon+php-dev@unequivocal.co.uk]
> Sent: Tuesday, September 05, 2000 2:53 PM
> To: Zeev Suraski
> Cc: php-dev@lists.php.net
> Subject: Re: [PHP-DEV] PHP File Upload Security Hole - Still No Fix?
>
> Can I suggest that adding in a concise syntax to access the variables
> would be an excellent idea? People are never going to sit there typing
> '$HTTP_POST_VARS' all the way through their script. Yes, you
> can add in
> a function in a library, but a lot of people aren't going to do that
> (and PHP's philosophy appears to be to put everything
> built-in anyway ;-) ).
>
> If you had a '%var' syntax, or a built-in function with a
> very short name,
> I think this would help immensely.